use-sapiom

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill's broad capabilities mostly match its stated purpose as a unified cloud-services gateway, and the MCP endpoint appears same-org and legitimate. However, it centralizes many sensitive data flows through Sapiom, enables outbound messaging and other real-world actions, and combines untrusted web ingestion with execution/storage/action tools, making the overall skill high risk even without clear malware indicators.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/sapiom%2Fskills%2Fuse-sapiom%2F@16a64c38f38f9d12fd07e79dcc4d9a0325c6c2cf